LAST UPDATED: 6 SEPTEMBER 2026
Privacy Policy
AntiTask is built on the principle that your data belongs to you. This policy explains what data the AntiTask Windows application and the web application at antitask.net process, with whom we share it, how we protect it, and how long we keep it and how it is deleted.
Tiếng Việt: the Vietnamese version of this policy is available at antitask.net/privacy. Both versions have the same meaning and effect.
1. Who we are
AntiTask is a personal task, calendar and note-taking application for Windows, published by the AntiTask developer team, with a companion web application at antitask.net. Contact: trinhngochai1508@gmail.com.
2. Data stored locally on your device
Tasks, projects, tags, notes, drawings, screenshots and application settings are stored entirely on your own Windows device in a local SQLite database. AntiTask operates no server that receives, reads, backs up or stores the content of this data.
3. Optional cloud synchronisation
- Google Drive: if you choose to connect your Google account, AntiTask stores your synchronised data and backups inside the application data area of your own Google Drive account.
- Google Calendar / Outlook Calendar: if connected, AntiTask reads calendar events only in order to display them alongside your tasks inside the application.
You can disconnect at any time inside the application, or revoke access from your account provider's settings.
4. Premium accounts
If you use the Premium edition, AntiTask processes your email address, Google account identifier, licence plan and licence expiry date solely to verify that your licence is valid. This information is never used for advertising and is never sold.
5. Google API access and Limited Use commitment
When you choose to connect a Google account, AntiTask requests exactly the following minimum OAuth scopes and no others:
- openid email profile — identifies the signed-in account (email address, account identifier, name and profile picture) so the app can show who is signed in and verify Premium licence entitlement.
- https://www.googleapis.com/auth/calendar.readonly — reads events from your Google Calendar so they can be displayed together with your tasks. AntiTask never creates, edits or deletes any event in your calendar. This scope is used by the Windows application only.
- https://www.googleapis.com/auth/drive.appdata — stores your synchronised data in the hidden, application-specific Application Data Folder of your own Google Drive. That area is private to AntiTask and cannot be read by other applications.
- https://www.googleapis.com/auth/drive.file — reads and manages only the files AntiTask itself created in your Google Drive, so synchronised attachments survive across versions. AntiTask cannot read or modify any other file in your Drive.
Google Limited Use Disclosure
AntiTask's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. With whom we share, transfer or disclose Google user data
6.1. Binding commitments
- No sale of data. We never sell, rent, trade or commercially transfer Google user data to any third party.
- No advertising or behavioural analytics. Google user data (calendar events, Drive files, identity information) is never shared with advertisers, behavioural analytics platforms, data brokers or marketing networks.
- No AI/ML training. Data obtained through Google APIs is never used or transferred to develop, improve, evaluate or train generalized artificial intelligence or machine learning models.
- No human access. No AntiTask employee or contractor reads your Google user data; we operate no server that holds it.
6.2. Complete list of recipients
AntiTask uses a direct device-to-Google architecture. Apart from you and Google, the only parties involved in processing are the infrastructure service providers listed below, strictly limited to the data shown:
| Recipient | Data transferred | Purpose |
|---|---|---|
| Google LLC (Google Drive, Google Calendar) | Synchronised data written into your own Google Drive application data folder; read requests against your own calendar | To deliver the synchronisation and calendar display features you enabled |
| Supabase, Inc. (authentication and licence database) | Only your email address, Google account identifier (sub), licence plan and expiry date. Never your tasks, notes, calendar events or Drive files | To authenticate your session and verify your Premium licence |
| payOS (payment gateway partner) | Only an order code and a payment amount. No Google user data at all | To process a Premium licence purchase, only if you choose to buy one |
| Cloudflare, Inc. (website infrastructure) | Technical request metadata when you visit antitask.net (IP address, browser type) and cookie-less aggregate traffic statistics. No Google user data | Website hosting and delivery, abuse protection, anonymous visit statistics |
We use no other third parties. These providers act solely as service providers processing data on our instructions for the purposes above, and are not permitted to use the data for their own purposes.
6.3. Other disclosures
Google user data is otherwise disclosed only: (1) on your explicit instruction or direct action (for example, when you choose to store a backup in your own Google Drive account); (2) where required to comply with applicable law, a court order or a valid governmental request; or (3) where necessary to detect or prevent fraud, or to protect the rights, property and safety of our users and of the application, as permitted by law.
7. How we protect sensitive data
AntiTask applies the following technical and organisational measures to protect sensitive data obtained through Google APIs:
- Encryption in transit. All traffic between AntiTask and Google, Supabase or antitask.net uses HTTPS with TLS 1.2 or higher. Unencrypted connections are refused.
- Encrypted credential storage. On Windows, Google access and refresh tokens are encrypted with the operating system's own encryption service (Windows DPAPI, through Electron safeStorage) before being written to disk, and are readable only by the current Windows user account. If OS-level encryption is unavailable, the application refuses to persist the token rather than writing it in plain text.
- Web application. At antitask.net/app the Google access token is kept only in your own browser storage to maintain your session, is never transmitted to any AntiTask server, and is removed when you sign out or clear site data. The web application is a static client that calls the Google Drive API directly from your browser.
- Zero intermediary server. Synchronisation runs directly between your device and Google. We operate no proxy or backend that stores, decrypts or inspects your tasks, notes, Drive files or calendar events.
- Access control on the licence system. The Premium licence database holds only email, account identifier and licence status. It is protected by Row Level Security so that each user can read only their own record; administrative service keys exist server-side only and are never shipped inside the application.
- Protection at rest. The local database is stored in the operating-system-protected user profile directory. Sensitive notes can additionally be locked with a master password chosen by you, hashed with PBKDF2; the password itself is never stored.
- Least privilege. Only the minimum scopes required by the published features are requested: read-only calendar access, and Drive access limited to the application data folder and to files the application itself created.
- Incident handling. If we become aware of a security incident affecting Google user data, we will investigate it, take corrective action and notify affected users without undue delay.
8. Data retention and deletion
8.1. Retention periods
- Google OAuth tokens. Held on your own device (or in your own browser for the web application) only for as long as your Google account remains connected. They are deleted immediately when you sign out or disconnect.
- Calendar data. Kept only in a local cache for display, refreshed at each synchronisation and deleted when you disconnect your Google account.
- Synchronised Drive data. Kept inside your own Google Drive application data folder until you delete it. We hold no copy on any server of ours. Daily restore points in that folder are rotated automatically, keeping at most the 14 most recent.
- Premium licence records. Email address, Google account identifier and licence status are retained while your account remains active, for licence verification and transaction record-keeping, and are deleted when you request account deletion.
8.2. How to delete your data
- Disconnect inside the app. Use the "Disconnect" button in AntiTask settings. This immediately deletes all stored OAuth tokens and all cached Google data from the device.
- Revoke access at Google. You can revoke AntiTask's access at any time at https://myaccount.google.com/permissions.
- Delete synced Drive data. Go to Google Drive > Settings > Manage Apps > AntiTask > Options > Delete hidden app data to permanently remove everything AntiTask stored in your Drive.
- Uninstall. Uninstalling AntiTask from Windows and removing its user-data folder erases the local database, caches and credentials from your computer.
- Account and data deletion request. Email trinhngochai1508@gmail.com with the subject "Data deletion request". We delete the records held on our systems, including the Premium licence record, and confirm completion to you within 30 days.
9. Children
AntiTask is not directed to children under 13 and we do not knowingly collect their data. If we learn that we hold such data, we delete it promptly after being notified.
10. Changes to this policy
We may update this policy to reflect product or legal changes. The date of the most recent update is always shown at the top of this page, and material changes are announced inside the application.
11. Contact
For any privacy question, request or complaint, contact us at trinhngochai1508@gmail.com.